LGPD entered into force on September 18, 2020. Administrative sanctions enforced by the ANPD became applicable on August 1, 2021.
Solutions / By Regulation
Operationalize Brazil's LGPD with consent management, data subject rights in Portuguese, RIPD assessments, and breach notification — coordinated with the ANPD's evolving guidance.
What is LGPD?
Brazil's Lei Geral de Proteção de Dados (LGPD), in force since September 2020 with sanctions effective August 2021, governs the processing of personal data by individuals and organizations in Brazil. It establishes ten lawful bases for processing, broad data subject rights, accountability obligations, and is enforced by the Autoridade Nacional de Proteção de Dados (ANPD).
Typical applicability thresholds
Key requirements
Identify and document one of LGPD's ten lawful bases (consent, legal obligation, contract, legitimate interest, etc.) for each processing activity.
Honor rights to confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, and revocation of consent.
Maintain Relatórios de Impacto à Proteção de Dados Pessoais for high-risk processing, particularly when relying on legitimate interest or processing sensitive data.
Appoint an Encarregado de Dados (DPO) responsible for receiving communications from data subjects and the ANPD.
Apply heightened protections — typically specific and prominent consent — for sensitive data and data of children and adolescents.
Use approved mechanisms (adequacy, standard contractual clauses, BCRs, certifications, specific consent, or other legal bases) for transfers outside Brazil.
Penalties & enforcement
The ANPD may impose warnings, simple fines up to 2% of the company group's revenue in Brazil per infraction (capped at R$50 million per infraction), daily fines, publication of the violation, blocking or deletion of personal data, and partial or full suspension of database operations.
How Clarip helps
Clarip unifies consent, data discovery, subject rights, and regulatory reporting — with workflows pre-configured for LGPD.
Quick answers to the questions privacy, legal, and engineering teams most often ask about LGPD.
LGPD entered into force on September 18, 2020. Administrative sanctions enforced by the ANPD became applicable on August 1, 2021.
Yes. LGPD applies to processing operations carried out in Brazil, processing aimed at offering goods or services to individuals in Brazilian territory, and processing of personal data collected in Brazil — regardless of where the controller is located.
LGPD provides ten lawful bases (Art. 7), including consent, compliance with a legal/regulatory obligation, execution of public policies, research, contract performance, exercise of rights in legal proceedings, protection of life, health protection, legitimate interest, and credit protection. Sensitive data has its own list of bases under Art. 11.
Yes, controllers must appoint an Encarregado de Dados, although the ANPD has issued resolutions allowing flexibility for small processing agents. The Encarregado serves as the contact for data subjects and the ANPD.
The ANPD can impose warnings, simple fines of up to 2% of the company group's revenue in Brazil (capped at R$50 million per infraction), daily fines, public disclosure of the violation, and blocking or deletion of the personal data involved.
Clarip provides Portuguese-language consent and rights portals, automated data mapping and ROPA aligned to ANPD guidance, RIPD templates with legitimate interest balancing tests, ANPD breach notification workflows, and Encarregado / international transfer recordkeeping.
Book a 30-minute walkthrough and a custom gap assessment against LGPDrequirements — mapped to the systems and vendors you already use.